View Full Version : Firewall hits
Variable
12-23-2003, 11:18 AM
Anyone else getting a lot of intrusion attempts? Im getting both TCP and UDP attempts.
jeeza
12-23-2003, 11:26 AM
What does one usually do in such cases ?
Look where these hits originated ?
I don't know, it's just an idea.
Maybe it's your ISP ?
Variable
12-23-2003, 11:35 AM
:)
Nah, it's not the ISP. It's random script kiddies most likely. I looked at the Storm Center and I don't see anything really out of the ordinary. Also the ports are always different. Normally I send a copy for the log to the admin in charge of the ISP allocated the ip of the intrusion. But, when I'm getting 4-5 hits every 45 minutes that's not normal. These are not Trojans.
I'm thinking of dropping NIS, I have blackice somewhere and I think ill try it. I need a more configurable firewall.
kayofcircles
12-23-2003, 01:11 PM
4 or 5 hits is wonderful in my eyes..that's what I used to get. Since last Sept, it's been increasing for me until I had to turn off the log part because would hit the 500 limit in my ZA log in about an hour and a half. Very dismaying, and I try not to be online very long. Now it's 300 to 400 in one hour and I am on slow dialup still.
Variable
12-23-2003, 01:57 PM
You probably have your zone alarm cofigured to log everything. Many times firewalls give false positives and if your getting hit 300-400 times an hour on dial up something is wrong. You need to know what kind of attempts are being logged. They are not all the same. Its possible your ZA is logging pings. I would suggest a network monitor like ethereal to nail down who is doing what. But, rest assured 300 hits an hour is NOT normal at all for a dial up user or any user for that matter.
vBulletin v3.6.1, Copyright ©2000-2010, Jelsoft Enterprises Ltd.